Security and subprocessors
Where your data lives, who can access it, and what protects it. This is the page referenced by the privacy policy and the data processing agreement.
Subprocessors
This is the complete list of providers that process data on Pinpost's behalf. Each is bound by protection obligations equivalent to ours.
| Provider | Role | Establishment | Data storage |
|---|---|---|---|
| Supabase | Base de données, authentification, fichiers | Singapour | Union européenne, région Francfort |
| Vercel | Hébergement de l'application et du site | États-Unis | Union européenne, région Francfort |
| Stripe | Paiement | Irlande et États-Unis | Union européenne |
| Resend | E-mails transactionnels | États-Unis | Union européenne, région européenne |
| Sentry | Erreurs techniques | États-Unis | Union européenne, région européenne |
| Plausible | Mesure d'audience sans cookie | Union européenne | Union européenne |
| Meta (Facebook) | Mesure publicitaire par pixel, avec consentement (CookieBanner.tsx) | Irlande et États-Unis | États-Unis |
Any addition to this list is subject to 30 days' notice, announced by email. During that period an agency may object in writing and, failing agreement, terminate at no cost.
Technical and organisational measures
Per-organisation isolation enforced at the database level: one organisation cannot read or write another's data, even if the application code gets it wrong. This rule is checked automatically on every change.
Encryption in transit and at rest.
Access and action log, kept for twelve months.
Daily backups, with a quarterly restore test.
Administrator access limited to metadata. Pinpost requests no access to your social network accounts, and therefore stores no token.
Transfers outside the European Union
Data is stored in the European Union, in the Frankfurt region. Some providers are established outside the EU and access from their home establishment remains possible for maintenance and support. These transfers are governed by the European Commission's standard contractual clauses, supplemented where applicable by the EU–US Data Privacy Framework. A copy of these safeguards is available on request at privacy@pinpost.cc.
In the event of a data breach
We notify the CNIL within 72 hours and inform the people concerned as soon as possible where the breach is likely to result in a risk to their rights and freedoms. A client agency is notified within 48 hours of discovery.
Report a vulnerability
Write to security@pinpost.cc. We acknowledge receipt without delay and keep you informed. No action will be taken against research conducted in good faith, without data exfiltration or degradation of the service.
If you received an approval link
You have no Pinpost account, your details were passed to us by the agency that invited you, and we use them only to show you the content and record your answer. The corresponding section of the privacy policy details what is collected and for how long.